Author Topic: Another consrv.dll Victim Needing Help  (Read 11347 times)

0 Members and 1 Guest are viewing this topic.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Another consrv.dll Victim Needing Help
« Reply #30 on: February 04, 2012, 07:00:58 PM »
OK lets check for damage

run farbar service scanner



Tick "All" options.
Press "Scan".
It will create a log (FSS.txt) in the same directory the tool is run.

Please copy and paste the log to your reply.

adc

  • Guest
Re: Another consrv.dll Victim Needing Help
« Reply #31 on: February 04, 2012, 07:22:56 PM »
Your link doesn't work, but I found it.  :)

FSS.txt attached.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Another consrv.dll Victim Needing Help
« Reply #32 on: February 04, 2012, 07:35:40 PM »
Oops my error a different forum software

Quote
MpsSvc Service is not running. Checking service configuration:
Checking Start type: Attention! Unable to open MpsSvc registry key. The service key does not exist.
Checking ImagePath: Attention! Unable to open MpsSvc registry key. The service key does not exist.
Checking ServiceDll: Attention! Unable to open MpsSvc registry key. The service key does not exist.

bfe Service is not running. Checking service configuration:
Checking Start type: Attention! Unable to open bfe registry key. The service key does not exist.
Checking ImagePath: Attention! Unable to open bfe registry key. The service key does not exist.
Checking ServiceDll: Attention! Unable to open bfe registry key. The service key does not exist.

wscsvc Service is not running. Checking service configuration:
Checking Start type: Attention! Unable to open wscsvc registry key. The service key does not exist.
Checking ImagePath: Attention! Unable to open wscsvc registry key. The service key does not exist.
Checking ServiceDll: Attention! Unable to open wscsvc registry key. The service key does not exist.

I am just going to upload to my site the registry keys that you are missing
Download them to your desktop
Right click each one and select merge
Accept the warnings and then re-run Farbar

https://skydrive.live.com/?cid=32D8666F4048075B&id=32D8666F4048075B%21117&sc=documents

Files are :
wscsvc.reg
bfe.reg
MpsSvc64.reg

adc

  • Guest
Re: Another consrv.dll Victim Needing Help
« Reply #33 on: February 04, 2012, 07:57:35 PM »
All 3 Reg files Merged successfully.

FSS.txt attached.


Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Another consrv.dll Victim Needing Help
« Reply #34 on: February 04, 2012, 09:51:15 PM »
Could you now reboot and try the firewall and defender

adc

  • Guest
Re: Another consrv.dll Victim Needing Help
« Reply #35 on: February 04, 2012, 10:10:06 PM »
Reboot...

Windows Defender is still stopped and issues an error when attempting to Start.

"The specified service does not exist as an installed service. (Error Code: 0x80070424)"

The Firewall is still giving the same error as before.
« Last Edit: February 04, 2012, 10:12:16 PM by adc »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Another consrv.dll Victim Needing Help
« Reply #36 on: February 04, 2012, 10:23:43 PM »
Well all the related files and keys are there so lets go for an automated fix to kick start them

Download  Windows Repair (all in one)  from this site

Install the programme then run

Go to step 2 and allow it to run Disc check (This stage can be skipped)


Once that is done then go to step 3 and allow it to run SFC



On the start repairs tab select advanced mode and click start


Select the items ticked(remove the ticks from the rest ) and tick restart system when finished

adc

  • Guest
Re: Another consrv.dll Victim Needing Help
« Reply #37 on: February 04, 2012, 11:26:47 PM »
Tweaking is still working hard at Step 5.... ::)

I forgot to tick Restart. Presume manual restart okay?
« Last Edit: February 04, 2012, 11:31:36 PM by adc »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Another consrv.dll Victim Needing Help
« Reply #38 on: February 04, 2012, 11:41:28 PM »
Aye that will work

Did the sfc scan do any changes ?

adc

  • Guest
Re: Another consrv.dll Victim Needing Help
« Reply #39 on: February 04, 2012, 11:47:29 PM »
Aye that will work

Did the sfc scan do any changes ?

SFC results indicated;

"Windows Resource Protection did not find any integrity violations."

Tweaking just finished. Asking for restart.

p.s.
It's getting to be pretty late where you are..

How much longer will you be available?
« Last Edit: February 04, 2012, 11:51:16 PM by adc »

adc

  • Guest
Re: Another consrv.dll Victim Needing Help
« Reply #40 on: February 04, 2012, 11:58:50 PM »
Machine is back up.

The Firewall and Defender are still down.
The Firewall error appears to have changed from "0x80070424"

Current error;
"Windows Firewall can't change some of your settings.
Error code 0x8007042c"


Can't restart Defender either.

adc

  • Guest
Re: Another consrv.dll Victim Needing Help
« Reply #41 on: February 05, 2012, 03:52:41 AM »
During the current lull period I ventured to the below Microsoft website and within the 11 pages I found the solution, as did many others. My Base Filtering Engine (BFE), Windows Firewall, Windows Defender are currently running.  :)

Error Code 0x80070424 with Windows Firewall, Defender in Windows 7

In addition I found that the protections on the laptop's 2nd Hard drive (D:) had been removed. Protection was probably disabled on D: drive during the recent Malware Attack, and rendered it unusable. I re-enabled protection on it to bring it back to life. :)

I will continue to monitor the operation of the laptop, and see if there is anything else that falls in the category of strange behavior of the OS.

For now everything is going okay, and I have attached a current FSS.exe scan. ;D

Thank you again for your expertise, and time.

I will be standing by in case you have any other requests.

Cheers,
Al
« Last Edit: February 05, 2012, 04:31:00 AM by adc »

adc

  • Guest
Re: Another consrv.dll Victim Needing Help
« Reply #42 on: February 05, 2012, 09:16:07 AM »
Essexboy,

I no longer have the laptop in my possession as the owner came tonight to pick it up.

It was recommended that the owner just shut the laptop off and bring it back to me immediately if the Fake Security Malware appears again. Hopefully the problem won't come back.  ::)

THX to all.  ;D  8)

Al


 

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Another consrv.dll Victim Needing Help
« Reply #43 on: February 05, 2012, 01:33:41 PM »
Yes that looked clear.  The problem I saw with the last Farbar scan was that the services were set to disabled and windows repair should have reset them as all the keys and files were in the right place just not started

The only follow up I was going to do was to remove the tools


adc

  • Guest
Re: Another consrv.dll Victim Needing Help
« Reply #44 on: February 05, 2012, 06:34:22 PM »
Yes that looked clear.  The problem I saw with the last Farbar scan was that the services were set to disabled and windows repair should have reset them as all the keys and files were in the right place just not started.

The only follow up I was going to do was to remove the tools

I received a call from the laptop's owner last late night, and he was very pleased that the malware infection was eliminated.  ;D

It was a pleasure to work with you.

Clean-up accomplished.  :)  Removing the tools, reg files, and logs was the last item of business before returning the laptop.  ;D 8)

Cheers,
Al